Show filters
104 Total Results
Displaying 21-30 of 104
Sort by:
Attacker Value
Unknown
CVE-2022-2337
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.
0
Attacker Value
Unknown
CVE-2022-2336
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.
0
Attacker Value
Unknown
CVE-2022-2335
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
0
Attacker Value
Unknown
CVE-2022-2334
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.
0
Attacker Value
Unknown
CVE-2022-1748
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.
0
Attacker Value
Unknown
CVE-2022-1373
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path traversal file may cause a file to be created and executed upon touching the disk.
0
Attacker Value
Unknown
CVE-2022-1069
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
0
Attacker Value
Unknown
CVE-2022-29824
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
0
Attacker Value
Unknown
CVE-2021-32994
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several unexpected memory locations.
0
Attacker Value
Unknown
CVE-2021-42577
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.
0